Data processed on your device
To save and switch website login states, LoginFlip processes applicable cookies, localStorage for the current full website origin, the active tab URL, account names, and website aliases. This data may include sensitive credentials capable of signing in to an account.
LoginFlip has no service account, developer server, cloud sync, telemetry, advertising, or third-party analytics SDK. Account data is not uploaded, sold, or shared with the developer or third parties. Websites still receive their own applicable cookies when Chrome opens or refreshes them; LoginFlip is not an anonymity tool.
Why permissions are required
cookies: capture, clear, and restore applicable regular and current same-site partitioned cookies.storage: keep accounts, preferences, workflow state, and limited recovery data locally. LoginFlip does not usestorage.sync.tabs: identify the current website, associate tabs, open websites, reload pages, and activate linked tabs.scripting: read and restore localStorage on an accessible page after checking its origin.http://*/*andhttps://*/*: support ordinary websites selected by the user and their applicable parent-domain cookies. LoginFlip does not automatically capture every visited website.
Storage, retention, backup, and deletion
Saved accounts, names, aliases, and preferences remain in Chrome extension local storage until the user deletes them or uninstalls LoginFlip. At most one previous snapshot per account and one failed-switch recovery record are retained and cleaned after 24 hours on a later initialization or write. Temporary workflows and tab associations use session storage and may disappear earlier.
Incognito and regular cookie stores are separate, but an account explicitly saved from an incognito window remains in extension local storage after the window closes. Exported backups are downloaded to a location chosen by the user. Encrypted backups are recommended; the passphrase is used locally for that operation and is not stored or uploaded. A plain JSON backup may contain usable login credentials.
Users can delete one account, all accounts for a website, previous snapshots, or failure-recovery data from LoginFlip. Deleting local data does not sign out or revoke the server-side account; use the website’s own security controls when revocation is required.
Publisher, compliance, and contact
Publisher: qingtan (individual developer, non-trader). Privacy contact: xinning000@gmail.com.
LoginFlip’s use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. LoginFlip does not sell user data or use it for advertising, credit decisions, or purposes unrelated to its single purpose, and it does not transfer login snapshots to third parties or developer-operated servers.